A security breach linked to Coldcard hardware wallets has resulted in confirmed losses of $115 million in bitcoin, according to the latest research from Galaxy Digital's research division. The figure, now validated by one of the crypto industry's most closely watched institutional research teams, marks one of the most significant cold storage security failures in Bitcoin's history — and forces an uncomfortable reckoning for a community that has long treated hardware wallets as the gold standard of self-custody.
The scale of the loss is difficult to overstate. At $115 million, this is not a rounding error or a minor operational slip. It is a breach that cuts to the heart of the self-custody ethos that has underpinned the Bitcoin security narrative for over a decade. Hardware wallets — physical devices designed to keep private keys air-gapped from internet-connected environments — exist precisely to prevent this kind of outcome. When that line of defense fails at nine-figure scale, the entire architecture of retail and institutional cold storage deserves scrutiny.
Coldcard, manufactured by Canadian firm Coinkite, has built a reputation as arguably the most security-focused consumer hardware wallet on the market. It is the device recommended in Bitcoin-only circles, favored by technically sophisticated users who distrust multisig shortcuts or custodial compromises. Its user base skews toward those who take self-sovereignty seriously. That profile makes the $115 million figure even more alarming: if this demographic is vulnerable, the attack vector is not a story about naive users making basic mistakes.
Galaxy Research's confirmation of the loss amount is significant not only for its precision but for what it implies about the investigative work required to arrive at that number. On-chain forensics at this scale require tracing fragmented outputs across potentially hundreds of wallet addresses, correlating transaction timing, and distinguishing affected funds from background Bitcoin movement. The fact that Galaxy's analysts have put a firm number to the breach suggests the theft has a traceable signature — meaning the methodology of the attack left identifiable patterns on the blockchain ledger.
The precise attack vector has not been fully elaborated in the available reporting, but the association with Coldcard raises several possibilities that the security community will be stress-testing in the days ahead. Supply chain compromise — where devices are tampered with before reaching end users — has been a documented threat in the hardware wallet space for years. Firmware vulnerabilities, seed phrase extraction through side-channel attacks, and social engineering targeting device initialization are also well-understood risks. What matters now is whether this breach represents a novel exploitation of Coldcard's specific architecture, or a known class of attack executed at unprecedented scale.
For the broader Bitcoin custody industry, the timing is particularly uncomfortable. Institutional adoption of Bitcoin has accelerated meaningfully through 2025 and into 2026, with exchange-traded fund inflows and corporate treasury allocations pushing more capital into self-custody and semi-custodial arrangements. Hardware wallets sit at the intersection of retail self-sovereignty and institutional cold storage infrastructure. A confirmed nine-figure loss tied to a specific device class will inevitably prompt custodians, family offices, and treasury managers to audit their own exposure — and may accelerate demand for multisignature schemes that distribute key risk across multiple devices and vendors.
It also raises pointed questions for regulators who have been deliberating over custody standards for digital assets. In the United States, the Securities and Exchange Commission and banking regulators have debated qualified custodian requirements for digital asset funds. A $115 million cold storage breach provides concrete ammunition for those who argue that hardware wallet custody, without additional institutional controls, is insufficient for large-scale asset protection. Expect this incident to surface in future regulatory commentary on custody risk.
Galaxy Research's role in surfacing and quantifying this breach underscores the growing importance of institutional-grade blockchain analytics in incident response. The crypto industry does not have a Federal Deposit Insurance Corporation backstop, no central authority issues binding incident disclosures, and affected users often have limited legal recourse. In that vacuum, research operations with on-chain forensic capabilities have become de facto first responders for public accountability. Galaxy's $115 million confirmation is, in practical terms, the closest thing to an official loss statement this incident is likely to receive in the near term.
What this means for the market is a renewed and urgent conversation about layered custody security. A single hardware wallet, however well-regarded, is a single point of failure. The $115 million Coldcard hack is a brutal illustration of that principle — one that the Bitcoin community will be processing long after the dust settles on the breach itself. Whether that conversation translates into structural change in how Bitcoin is stored, or fades into another cautionary anecdote, will define a meaningful chapter in the maturation of digital asset security.
Written by the editorial team — independent journalism powered by Bitcoin News.